Artefatto di rilevamento Python che verifica le istanze Atlassian Jira, Confluence e Bitbucket per la vulnerabilità di lettura arbitraria di file CVE-2026-21589.
CVE-2026-21589 - Lettura arbitraria di file in Jira/Confluence/Bitbucket
Il Detection Artifact Generator tenta di verificare se il target è vulnerabile a CVE-2026-21589. Il rilevamento è implementato per i seguenti prodotti:
È necessario fornire i seguenti input:
-H - host di destinazione.Esecuzione di esempio contro un'istanza Jira vulnerabile:
$ python3 watchTowr-vs-Atlassian-CVE-2026-21589.py -H http://jira.lab.local:8080
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-Atlassian-CVE-2026-21589.py
(*) CVE-2026-21589 - Jira/Confluence/Bitbucket Arbitrary File Read Detection Artifact Generator
- Piotr | Sonny | Yordan of watchTowr (@watchTowrcyber)
[+] Starting CVE-2026-21589 DAG
[+] Attempting to send payloads for Jira, Confluence and Bitbucket
[+] Found VULNERABLE Jira instance
Esecuzione di esempio contro un'istanza corretta:
$ python3 watchTowr-vs-Atlassian-CVE-2026-21589.py -H http://jirapatch.lab.local:8080
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-Atlassian-CVE-2026-21589.py
(*) CVE-2026-21589 - Jira/Confluence/Bitbucket Arbitrary File Read Detection Artifact Generator
- Piotr | Sonny | Yordan of watchTowr (@watchTowrcyber)
[+] Starting CVE-2026-21589 DAG
[+] Attempting to send payloads for Jira, Confluence and Bitbucket
[-] Unknown response - probably NOT VULNERABLE
Questo script tenta di rilevare se Jira/Confluence/Bitbucket è vulnerabile alla vulnerabilità di lettura arbitraria di file CVE-2026-21589.
L'elenco completo delle versioni interessate è disponibile qui vendor advisory:
Secondo l'avviso ufficiale, le versioni corrette sono:
Bitbucket Data Center
Confluence Data Center
Jira Service Management Data Center
Jira Software Data Center
Bamboo Data Center
Crowd Data Center
Crucible
Fisheye
Per le ultime ricerche sulla sicurezza segui il team watchTowr Labs